Impact
The Cloudflare Email Worker used by PunchIn-App’s punchin-email drops the Reply-To header when forwarding inbound mail, causing the operator’s private FORWARD_TO address to appear in the reply that is sent to external correspondents. Based on the description, it is inferred that this disclosure allows anyone who receives a message from the operator to see the operator’s private email address, potentially enabling unintended direct contact or phishing attempts, but does not provide code execution or access to additional confidential data.
Affected Systems
Versions of punchin-email prior to 1.5.0 are affected. The vulnerability is triggered when handleInbound delivers inbound alias mail with message.forward(), so any instance of the worker that performs this action before the fix will expose the operator’s address. No third‑party data is exposed beyond the operator’s own address.
Risk and Exploitability
The CVSS score of 2.1 indicates low severity, and the EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attack is limited to the operator; an attacker must be able to view the operator’s replies. Based on the description, it is inferred that this is typically possible for any correspondent. There is no remote code execution or elevated privilege exploitation involved.
OpenCVE Enrichment